icon

We found results for “

CVE-2025-66675

Good to know:

icon
icon
icon

Date: December 10, 2025

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue. It's related to  https://cve.org/CVERecord?id=CVE-2025-64775  - this CVE addresses missing affected version 6.7.4

Severity Score

Severity Score

Weakness Type (CWE)

Incomplete Cleanup

CWE-459

Top Fix

icon

Upgrade Version

Upgrade to version org.apache.struts:struts2-core:6.8.0;org.apache.struts:struts2-core:7.1.1;org.apache.struts:struts2-core:6.8.0;org.apache.struts:struts2-core:7.1.1;https://github.com/apache/struts.git - STRUTS_6_8_0;https://github.com/apache/struts.git - STRUTS_7_1_1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us